browser-automation

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
references/anti_detection_patterns.md

This code fragment functions as an abuse-enabling “stealth/evasion toolkit” for Playwright automation: it injects scripts to remove automation indicators, spoofs multiple high-signal browser fingerprint surfaces (navigator properties, WebGL vendor/renderer, canvas pixel output), and simulates human-like interaction timing, with optional proxy routing. While there is no clear evidence of credential theft, persistence, or exfiltration in the provided snippet, its explicit anti-detection design materially increases the likelihood of bypassing access controls and performing potentially unauthorized scraping. Treat as high misuse risk rather than confirmed self-contained malware.

Confidence: 74%Severity: 70%
Audit Metadata
Analyzed At
Sep 4, 2026, 02:34 PM
Package URL
pkg:socket/skills-sh/iwanhe%2Fpandawa%2Fbrowser-automation%2F@be392b55a77d2854394bda863305a367ff6bc691afedfcf341406452a267a341
Security Audit — socket — browser-automation